CVE-2001-0373: Low severity Microsoft Windows 2000 vulnerability
Published Jun 18, 2001
·Updated
The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information.
Affected Software
2 affected components
Microsoft Windows 2000
Microsoft Windows NT=4.0
Remediation
Patch Available
Event History
Jun 18, 2001
CVE Published
04:00 AM
Mar 9, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0373?
CVE-2001-0373 is considered a moderate vulnerability due to the exposure of sensitive information.
2
How do I fix CVE-2001-0373?
To fix CVE-2001-0373, change the permissions on the user.dmp files to restrict access to authorized users only.
3
What systems are affected by CVE-2001-0373?
CVE-2001-0373 affects Microsoft Windows NT 4.0 and Microsoft Windows 2000.
4
What type of information can be exposed due to CVE-2001-0373?
CVE-2001-0373 can expose sensitive information such as user credentials and application data.
5
Is there a workaround for CVE-2001-0373?
A workaround for CVE-2001-0373 is to disable the generation of crash dump files in the Dr. Watson configuration.